Impact
CVE-2026-33937 affects Handlebars versions 4.0.0 through 4.7.8. Advisory sources describe code injection when an attacker can supply a crafted pre-parsed AST object to Handlebars.compile(); Handlebars 4.7.9 contains the fix [S1][S2][S3].
For a deployed application, risk depends on more than the package version. The application must use an affected Handlebars runtime and allow attacker-controlled object or JSON data to reach compile() as an AST-like value rather than a trusted template string.
Root Cause
Affected Handlebars releases accepted a pre-parsed AST object as input to compile() in addition to a template string. The vulnerable compiler path emitted NumberLiteral values into generated JavaScript without the validation needed to keep those values numeric [S1][S3].
How FixVibe covers it
FixVibe's GitHub repo scans flag npm manifests and lockfiles that resolve handlebars versions in the affected range for CVE-2026-33937 / GHSA-2w6w-674q-4c4q, with the dependency file, version and fixed version.
Concrete Fixes
Upgrade handlebars to 4.7.9 or newer, regenerate the active npm, pnpm, or Yarn lockfile, rebuild every server, worker, SSR bundle, container layer, and build artifact that installs it, and rerun the FixVibe GitHub repo scan [S1][S4].
Review every Handlebars.compile() call that can process request bodies, webhooks, CMS/admin template input, queued jobs, or tenant-controlled data. Enforce a string input contract before compilation, reject object or AST input at API and worker boundaries, and use handlebars/runtime where templates are precompiled and runtime compilation is unnecessary [S1][S3].
